A couple of security researchers have discovered that one of the internet’s most boring conventions, the fake “no reply” email address, can accidentally become a massive pipeline for private information, according to Wired.
Wired writes that security researcher Cory Solovewicz owns the domains noreply.net and noreply.us. Instead of being digital dead ends, the domains have been flooded with emails that companies apparently assumed nobody would ever receive. Since late 2024, noreply.net alone has collected roughly 400,000 messages, including more than 28,000 with attachments.
And this isn't ordinary spam. Solovewicz has received everything from government injury reports and repair orders to school account information and login credentials. In some cases, companies appear to be sending automated messages to addresses such as [email protected] under the assumption that the messages simply disappear.
“I created an accidental honeypot,” Solovewicz said. What began as a personal email experiment ev